We believe in collaborative security. Help us keep Sitemap.xml safe, and we'll reward your expertise. Responsible disclosure is always welcome.
📧 Submit a ReportFocus your efforts on our core infrastructure and APIs. We reward targeted, responsible testing.
We compensate fairly based on impact, exploitability, and effort. All payouts are issued within 14 days of verification.
RCE, complete account takeover, mass data breach, or authentication bypass affecting all users.
SQLi, XSS (stored/reflected), IDOR, privilege escalation, or sensitive data exposure.
CSRF, open redirects, rate limit bypass, session fixation, or minor info leaks.
Security headers missing, minor misconfigurations, or best practice improvements.
Follow these steps to ensure your report is processed quickly and rewarded fairly.
Provide a clear description, steps to reproduce, impact assessment, and proof-of-concept. Include HTTP requests/responses where applicable.
Send your report to our dedicated security inbox. Use PGP encryption if preferred. We acknowledge all submissions within 48 hours.
Our security team will triage, reproduce, and fix the issue. We'll keep you updated throughout the process and notify you when patched.
Once verified and resolved, rewards are processed via PayPal, Wise, or crypto. Hall of Fame recognition is optional.
We will not initiate legal action against anyone who identifies and responsibly discloses security vulnerabilities. Your good-faith efforts are protected under our Responsible Disclosure Policy.